Live data from Hacker News

Viewing profile — anderslemke

anderslemke

HN member
Joined
Mon, Feb 04, 2019, 9:08 AM UTC
HN karma
44
Public activity
18 items

About anderslemke

No profile information was provided.

Recent public activity

  1. comment
    Comment #25252076

    I get where you're coming from, and this is something I've been thinking a lot about. It would be possible to not save the map, and then use some kind of hashing to infer user ids …

  2. comment
    Comment #25114529

    Yes. Promise keeps a map of your sites and IDs.

  3. comment
    Comment #25109781

    Promise is basically challenging the assumption that authentication has anything to do with both personal identity and being able to contact a user. If a site needs to contact the …

  4. comment
    Comment #25104230

    I'm really happy that you're willing to take this discussion with me. I totally understand what makes IndieAuth is a good solution. And it seems really easy. For me. But I have no …

  5. comment
    Comment #25099695

    Being a non-profit, collectively owned service, which Promise is, will make it difficult to ban users and relying parties. Just like the DNS can block users, Promise can ban users …

  6. comment
    Comment #25099186

    That is an interesting point. Internet identity could maybe be a layered thing where one layer takes care of authentication, which is where Promise lives. The next layer could hand…

  7. comment
    Comment #25096457

    That sounds painful in so many ways...

  8. comment
    Comment #25096401

    Yes. The fragmentation is part of what makes authentication a horrible experience. But most of all, what I'm missing is at least one good option on the sign-in screen. And using a …

  9. comment
    Comment #25096290

    I didn't know SimpleLogin. It seems really nice. Kind of what Apple does with their "Sign In with Apple". It's not exactly a SSO, though.

  10. comment
    Comment #25096166

    Being pseudonymous is one of the main selling points of Promise. Only by being pseudonymous can it provide the level of privacy that should be expected from the global authenticati…

  11. comment
    Comment #25096111

    I would love to understand the reasoning here. Sincerely. What makes OIDC a "non starter"? I see OIDC as an implementation detail, and have no strong opinions about it.

  12. comment
    Comment #25096072

    Ok, you're not the first to say that... I hate it, when I type my email and password (correct, that is), and get an error saying "You already have an account. You need to sign in".…

  13. comment
    Comment #25096024

    WebAuthn is great! I don't see any reason why Promise shouldn't implement it. I see it this way, that Promise makes it possible for all its relying parties leverage WebAuthn by imp…

  14. comment
    Comment #25095965

    I'm a bit divided on whether or not the "centralized" thing is actually a problem Promise should tackle. On one hand, I want to tell you that Promise is only centralized by default…

  15. comment
    Comment #25093010

    I've built Promise, to prove (to myself at least), that it would be technically possible to build authentication infrastructure, that can be used across sites, without having to st…

  16. comment
    Comment #25092808

    The risk of getting your account locked is just one of the reasons you shouldn't use Google (and the like) to sign in. But how did we end up in this horrible state of authenticatio…

  17. comment
    Comment #23956575

    Hi benzgou. It seems login.land is down. What happened?

  18. comment
    Comment #23956419

    login.land seems to be down. What happened?